Challenge Medium

Forward a Port Using the Hackers' Swiss Army Knife: netcat

Prove your networking skills by setting up an improvised proxy server with netcat.

Premium Challenge

Upgrade your membership to unlock this and all other premium materials.

Upgrade

Similar to the socat challenge, you need to make an already running service available on a different port. However, this time you'll have to use the nc command.

There is an HTTP service listening on port 127.0.0.1:5000. Your task is to map this address to 0.0.0.0:6000. You're not allowed to change the service configuration or restart it.

Port forwarding vs. direct socket access.

Port forwarding vs. direct socket access. Note: The IP addresses and ports on the diagram are chosen arbitrarily.

Hint 1

Port forwarding a.k.a. port mapping is a form of Network Address Translation (NAT) that redirects packets from one address to another. Linux has a number of lower-level networking tools to implement it, so there is no need to bring in a full-blown proxy like Envoy, Nginx, or Caddy.

User-space port forwarding with a proxy process redirecting the packets.

Port forwarding with a user-space proxy (socat, netcat, etc.). Note: The IP addresses and ports on the diagram are chosen arbitrarily.

Hint 2

netcat is a versatile networking utility that, in particular, can be used to start a listening TCP socket.

Hint 3

Unlike socat, netcat doesn't have a built-in proxy mode where connections are accepted on one port and forwarded to another. However, with netcat you can perform arbitrary commands upon receiving a connection. The data received from the client will be forwarded to the stdin of such command.

Hint 4

netcat can also be used to connect to a TCP socket and forward data from the stdin.

Hint 5

How about combining the two previous hints? 😉

Hint 6

Not every version of netcat supports staying listening for another connection after its current connection is completed. If the -k option is not available, you'll have to be a bit more creative.

Hint 7

Use the force a bash loop, Luke! 🚀